CISA Warns of Trio of Actively Exploited SharePoint Server Flaws (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164)

CISA Warns of Trio of Actively Exploited SharePoint Server (TL-2026-1378), also tracked as SharePoint Trio Advisory, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-15 and last reviewed 2026-08-09. It is attributed to Storm-2603 (China) with medium confidence, affects Microsoft SharePoint Server Subscription Edition, references 6 CVEs (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), maps to 46 MITRE ATT&CK techniques (T1003, T1005, T1014), and is covered by 9 detection rules and 50 indicators of compromise.

Key facts for TL-2026-1378

Threat ID
TL-2026-1378
Also known as
SharePoint Trio Advisory, CISA July 2026 SharePoint Hardening Alert
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-07-15
Last reviewed
2026-08-09
Attribution
Storm-2603
Attribution confidence
MEDIUM
Nation-state nexus
China
Motivation
FINANCIAL
Target sectors
government administration, finance, health, education, technology, manufacturing, critical infrastructure, energy
Target regions
North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
50
Updates
2026-08-09 · 3 updates · revalidated 3× · latest source

Malware and tooling in CISA Warns of Trio of Actively Exploited SharePoint Server

Malware and tooling: WarLock, Storm-2603 activity cluster / CL-CRI-1040

CISA issued an advisory on July 14, 2026 warning that three on-premises Microsoft SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) are under active exploitation, with attackers gaining remote code execution and post-compromise persistence via theft of IIS/ASP.NET machine keys and deserialization abuse. Two additional July 2026 Patch Tuesday flaws (CVE-2026-55040, CVE-2026-58644) are rated 'Exploitation More Likely' but not yet confirmed exploited.

How CISA Warns of Trio of Actively Exploited SharePoint Server works

On July 14, 2026, CISA published an advisory urging administrators to harden on-premises Microsoft SharePoint Server deployments after confirming active, in-the-wild exploitation of three vulnerabilities: CVE-2026-32201 (CVSS 6.5, spoofing via improper input validation enabling unauthenticated reflected XSS/impersonation, disclosed March 2026 and added to CISA's KEV catalog on 2026-04-14), CVE-2026-45659 (CVSS 8.8, remote code execution via deserialization of untrusted data, requiring only Site Member-level authentication, patched May 2026 and added to KEV on 2026-07-01 despite Microsoft's initial 'exploitation less likely' rating), and CVE-2026-56164 (CVSS 5.3, elevation of privilege via missing authentication for a critical function, shipped in July 2026 Patch Tuesday and added to KEV the same day it was disclosed, 2026-07-14).

All three affect every supported on-premises SharePoint Server edition (Subscription Edition, 2019, and 2016/Enterprise Server 2016); SharePoint Online/Microsoft 365 is not affected. Post-exploitation activity observed by CISA and Microsoft involves theft of IIS/ASP.NET machine keys and abuse of .NET deserialization to forge authentication tokens, maintain persistence across patch cycles, and deploy malware. This tradecraft mirrors the July 2025 'ToolShell' SharePoint campaign (CVE-2025-49704/49706/53770/53771), in which the China-based actor Storm-2603 (aka Warlock Group / GOLD SALEM), along with Linen Typhoon and Violet Typhoon, exploited on-prem SharePoint to drop the spinstall0.aspx web shell, exfiltrate ASP.NET machine keys via a crafted GET request, establish persistence through scheduled tasks and Group Policy Object modification, and ultimately deploy Warlock ransomware via DLL search-order hijacking. Storm-2603 has continued targeting on-prem SharePoint with the same machine-key-theft objective roughly a year later, reusing the tactic against the newly disclosed 2026 CVEs.

Two further July 2026 Patch Tuesday SharePoint flaws are not yet confirmed exploited but carry Microsoft's 'Exploitation More Likely' designation and CISA flagged them as high-priority: CVE-2026-55040 (CVSS 9.1, critical security-feature bypass; the first half of a two-bug chain whose second, still-embargoed component is expected to complete an unauthenticated RCE chain in August 2026) and CVE-2026-58644 (CVSS 9.8, critical unauthenticated network RCE). Shadowserver telemetry cited in coverage counted roughly 10,000 internet-exposed on-prem SharePoint instances, with over 800 still unpatched against CVE-2026-32201 and CVE-2026-45659 as of the advisory date. CISA's Binding Operational Directive timeline required FCEB agencies to remediate CVE-2026-45659 by 2026-07-04 and the newly added CVE-2026-56164/CVE-2026-32201 exploitation by 2026-07-17. Recommended mitigations include immediate patching, enabling AMSI integration for SharePoint (to catch malicious POST requests), deploying Microsoft Defender AV, placing a Layer 7 reverse proxy in front of SharePoint, restricting external access to SharePoint Central Administration, rotating ASP.NET machine keys after patching, and enhanced logging for anomalous IIS/w3wp.exe activity.

MITRE ATT&CK techniques used in TL-2026-1378

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1556 Modify Authentication Process; T1606 Forge Web Credentials

Collection

T1005 Data from Local System; T1074 Data Staged; T1560 Archive Collected Data

Defense Evasion

T1014 Rootkit; T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Defense Evasion

Lateral Movement

T1021 Remote Services; T1210 Exploitation of Remote Services; T1550 Use Alternate Authentication Material; T1570 Lateral Tool Transfer

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1078 Valid Accounts; T1098 Account Manipulation; T1505 Server Software Component

Execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1134 Access Token Manipulation; T1484 Domain or Tenant Policy Modification

Command and Control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1219 Remote Access Tools; T1572 Protocol Tunneling

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

defense-impairment

T1112 Modify Registry; T1685 Disable or Modify Tools

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery

stealth

T1574 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1588 Obtain Capabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in CISA Warns of Trio of Actively Exploited SharePoint Server

  • Microsoft — SharePoint Server Subscription Edition
    Vulnerable versions: all builds prior to July 2026 cumulative update
    Fixed in: July 2026 Patch Tuesday cumulative update
  • Microsoft — SharePoint Server 2019
    Vulnerable versions: all builds prior to July 2026 security update
    Fixed in: July 2026 security update (KB per Microsoft Update Catalog)
  • Microsoft — SharePoint Enterprise Server 2016
    Vulnerable versions: all builds prior to July 2026 security update
    Fixed in: July 2026 security update (KB per Microsoft Update Catalog)

Remediation for CISA Warns of Trio of Actively Exploited SharePoint Server

Patches

  • Microsoft April 2026 Patch Tuesday update — CVE-2026-32201
  • Microsoft May 2026 Patch Tuesday update — CVE-2026-45659
  • Microsoft July 2026 Patch Tuesday update — CVE-2026-56164, CVE-2026-55040, CVE-2026-58644

Immediate actions

  • Apply Microsoft's May 2026 and July 2026 SharePoint security updates covering CVE-2026-45659, CVE-2026-56164, CVE-2026-55040, and CVE-2026-58644 without delay
  • Rotate ASP.NET/IIS machine keys on all on-premises SharePoint Server instances after patching, since theft of the pre-existing keys survives a patch alone
  • Restrict or remove external/internet exposure of SharePoint Central Administration
  • Hunt for spinstall0.aspx and similarly-named .aspx artifacts (spinstall1.aspx, spinstall2.aspx) dropped into LAYOUTS directories

Workarounds

  • Where immediate patching is not possible, isolate on-prem SharePoint Server from the internet and restrict access to a trusted VPN/reverse-proxy path
  • Monitor for and block outbound connections to ngrok and similar tunneling services from SharePoint application servers

Longer-term hardening

  • Enable Windows Antimalware Scan Interface (AMSI) integration for SharePoint to scan and block malicious POST request bodies
  • Deploy Microsoft Defender Antivirus (or equivalent EDR) with up-to-date detections on all SharePoint front-end and application servers
  • Place a Layer 7 reverse proxy / WAF in front of internet-facing SharePoint deployments
  • Establish enhanced logging and alerting on anomalous w3wp.exe child-process activity, scheduled task creation, and Group Policy Object changes

CVEs associated with CISA Warns of Trio of Actively Exploited SharePoint Server

CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-55040, CVE-2026-58644, CVE-2026-50522

Weaknesses (CWE) in CISA Warns of Trio of Actively Exploited SharePoint Server

CWE-290, CWE-79, CWE-502, CWE-306, CWE-288, CWE-20, CWE-1390

Timeline of CISA Warns of Trio of Actively Exploited SharePoint Server

Showing the 20 most recent tracked events.

  • CISA adds CVE-2026-45659 to the KEV catalog after confirming active in-the-wild exploitation despite the patch having shipped in May.
  • CISA Binding Operational Directive remediation deadline for FCEB agencies to patch CVE-2026-45659.
  • Microsoft July 2026 Patch Tuesday releases security updates for multiple SharePoint Server vulnerabilities including CVE-2026-50522 and CVE-2026-56164; CISA issues SharePoint hardening alert urging AMSI Full Mode and machine key rotation.
  • CISA publishes the advisory 'CISA Urges SharePoint Hardening After New Exploitations,' warning of active exploitation of the three CVEs and highlighting IIS machine-key theft and deserialization post-exploitation tradecraft.
  • CISA adds CVE-2026-56164 to the KEV catalog the same day it is disclosed, citing active exploitation via missing authentication for a critical function.
  • Microsoft's July 2026 Patch Tuesday (622 CVEs total) discloses CVE-2026-56164, CVE-2026-55040, and CVE-2026-58644 affecting on-prem SharePoint Server.
  • Microsoft updates its advisory for CVE-2026-58644 (deserialization RCE, CVSS 9.8) to confirm active exploitation detected in the wild, days after July 2026 Patch Tuesday disclosure.
  • The Register, BleepingComputer, and other outlets report on the CISA advisory, noting Shadowserver telemetry of ~10,000 internet-exposed SharePoint instances with 800+ unpatched hosts.
  • CISA adds CVE-2026-58644 (SharePoint unauthenticated deserialization RCE, CVSS 9.8) to the KEV catalog, confirming active exploitation of a flaw the advisory had only rated 'Exploitation More Likely.'
  • Tenable publishes a consolidated FAQ on the chained SharePoint exploitation, summarizing CVSS/VPR scoring, AMSI/Defender IOCs (AK47 C2, NSecKrnl.sys BYOVD, LockBit Black), and mitigation guidance.
  • Defused security researchers detect an undocumented SharePoint deserialization vector in active attacks, initially unable to tie it to a specific CVE.
  • CISA Binding Operational Directive remediation deadline for FCEB agencies to address CVE-2026-32201 and CVE-2026-56164 exploitation.
  • Security researcher Janggggg publishes a public PowerShell PoC exploit for CVE-2026-50522 on GitHub; watchTowr confirms structural legitimacy and captures active exploitation attempts within hours via its Attacker Eye honeypot network.
  • CISA adds CVE-2026-50522 to the KEV catalog with a remediation deadline of July 25, 2026; Microsoft publishes a security blog detailing Storm-2603 activity delivering Warlock ransomware via exploited SharePoint servers.
  • CERT-EU issues Security Advisory 2026-009 warning EU institutions of active exploitation and recommending immediate patching, credential rotation, and compromise assessments.
  • FOITT (Switzerland's Federal Office for Information Technology, Systems and Telecommunication) security specialists detect anomalous access patterns on its on-premises SharePoint servers.
  • FOITT confirms approximately 200 user and technical accounts compromised; initiates incident response including password resets and full server reinstallation.
  • FOITT publicly discloses the cyberattack, attributing it to 'previously unknown actors' presumably exploiting the SharePoint vulnerability chain; investigation supported by Switzerland's BACS and Microsoft.
  • BleepingComputer is first to publicly report the Swiss government SharePoint breach, naming the agency as BIT (Federal Office of Information Technology, Systems and Telecommunication) and tying the suspected root cause specifically to CVE-2026-56164 and/or CVE-2026-50522.
  • Help Net Security and Cyber Security News publish additional coverage; BIT confirms affected servers are being reinstalled and external access remains blocked pending completion, with no threat actor having claimed responsibility and no evidence of data exfiltration beyond the ~200 compromised account credentials.

Update history for TL-2026-1378

Sources cited for CISA Warns of Trio of Actively Exploited SharePoint Server

Threats related to CISA Warns of Trio of Actively Exploited SharePoint Server

Detection coverage for TL-2026-1378

As of 2026-08-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1378 across Splunk SPL, Microsoft KQL and Sigma, covering 50 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats